ci: upgrade to Changesets v3 and changesets/action v2 (#401) #168
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Release | |
| env: | |
| # Version here should match the one in React Native template and packages/cmake-rn/src/cli.ts | |
| NDK_VERSION: 27.1.12297006 | |
| # pnpm records GitHub git dependencies (e.g. node-addon-examples) with an SSH | |
| # repo URL, which anonymous CI runners can't clone. Rewrite git@github.com: to | |
| # HTTPS so the public repo is fetched over HTTPS. | |
| GIT_CONFIG_COUNT: 1 | |
| GIT_CONFIG_KEY_0: "url.https://github.com/.insteadOf" | |
| GIT_CONFIG_VALUE_0: "git@github.com:" | |
| on: | |
| push: | |
| branches: | |
| - main | |
| concurrency: ${{ github.workflow }}-${{ github.ref }} | |
| jobs: | |
| release: | |
| name: Release | |
| runs-on: macos-latest | |
| environment: main | |
| # Publishing to NPM happens through trusted publishing, which needs an OIDC | |
| # token. Declaring permissions at all narrows them to exactly what is listed, | |
| # so the two the changesets action already relied on are spelled out too. | |
| permissions: | |
| contents: write # version commits, git tags and GitHub releases | |
| pull-requests: write # the "Version Packages" pull request | |
| id-token: write # NPM trusted publishing | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: pnpm/action-setup@v4 | |
| - uses: actions/setup-node@v6 | |
| with: | |
| node-version: lts/krypton | |
| cache: pnpm | |
| - name: Setup cpp tools | |
| uses: aminya/setup-cpp@v1 | |
| with: | |
| clang-format: true | |
| - name: ccache | |
| uses: hendrikmuhs/ccache-action@v1.2 | |
| with: | |
| key: ${{ github.job }}-${{ runner.os }} | |
| - name: Set up JDK 17 | |
| uses: actions/setup-java@v3 | |
| with: | |
| java-version: "17" | |
| distribution: "temurin" | |
| - name: Setup Android SDK | |
| uses: android-actions/setup-android@v3 | |
| with: | |
| packages: tools platform-tools ndk;${{ env.NDK_VERSION }} | |
| - run: rustup target add x86_64-linux-android aarch64-linux-android armv7-linux-androideabi i686-linux-android aarch64-apple-ios-sim | |
| - run: pnpm install | |
| - name: Create Release Pull Request or Publish to NPM | |
| id: changesets | |
| uses: changesets/action@v2 | |
| with: | |
| publish-script: pnpm run release | |
| env: | |
| # changeset publish detects the pnpm lockfile and correctly shells out | |
| # to `pnpm info`/`pnpm pack`/`pnpm publish` instead of npm's — but | |
| # `pnpm info` is itself a documented passthrough to the real npm CLI | |
| # (confirmed by strace: `pnpm info <pkg>` execs `npm info <pkg>`), so | |
| # it still runs into npm ≥ 11 validating this repo's own root | |
| # package.json on every invocation and failing with EBADDEVENGINES | |
| # (we declare devEngines.packageManager: pnpm, but the process | |
| # running is npm). `pnpm pack`/`pnpm publish` don't shell out to npm | |
| # and are unaffected. Passing force downgrades the devEngines error | |
| # to a warning; this is pnpm's own `info` implementation, so there's | |
| # no changesets- or pnpm-version bump that removes the need for it. | |
| npm_config_force: true |